What happened
Kobako embeds a Wasm-isolated mruby interpreter so untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, plugins) run in-process without host access. From 0.1.0 to before 0.9.1 the isolation is broken: a guest script can escape the sandbox (guest eval reaching host RCE via method_missing → public_send on bound services). Patched in 0.9.1.
Why it matters
This is the exact trust boundary AI platforms rely on to safely execute model-generated code in-process. A CVSS-10 sandbox escape means any prompt-injected or malicious LLM-generated script is host code execution, not sandboxed execution — a direct AI-deployment RCE primitive.
Attack vector
A guest mruby script (LLM-generated code, user formula, plugin) submitted to the sandbox escapes isolation and executes arbitrary Ruby in the host process — reaching host memory, files, network, and credentials the sandbox is designed to protect.
Affected systems
Kobako Ruby gem 0.1.0 through < 0.9.1
Mitigation
Upgrade to Kobako 0.9.1 or later (patched version).